PT-2007-7085 · Hewlett Packard · Hp-Ux
Published
2007-12-12
·
Updated
2018-10-15
·
CVE-2007-6195
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
HP-UX versions B.11.11 through B.11.23
Description
The issue is related to a buffer overflow in the
sw rpc agent init function in swagentd within Software Distributor (SD) and possibly other DCE applications. This allows remote attackers to execute arbitrary code or cause a denial of service by sending malformed arguments in an opcode 0x04 DCE RPC request.Recommendations
For HP-UX versions B.11.11 through B.11.23, consider restricting access to the
swagentd service until a patch is available. As a temporary workaround, avoid using the sw rpc agent init function in swagentd to minimize the risk of exploitation.Fix
RCE
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp-Ux